Replies: 1 comment
-
@rroupski have we determined the next steps here? |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
With that said, named Pipes events to have multiple unique fields (ENUMs) that aren`t relevant to the existing file events but that are needed for threat hunting/analysis. For example:
For more info see https://learn.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-createnamedpipea
With the above in mind, it might be worth having a dedicated class for Named Pipes.
0 votes ·
Beta Was this translation helpful? Give feedback.
All reactions